[Git][security-tracker-team/security-tracker][master] 10 commits: CVE-2022-41649,openimageio: Link to fixing commit

Markus Koschany (@apo) apo at debian.org
Sun Mar 19 22:44:27 GMT 2023



Markus Koschany pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d00da44c by Markus Koschany at 2023-03-19T23:43:52+01:00
CVE-2022-41649,openimageio: Link to fixing commit

- - - - -
0b8e81cb by Markus Koschany at 2023-03-19T23:43:53+01:00
CVE-2022-41684,openimageio: Link to fixing commit

- - - - -
3c7270da by Markus Koschany at 2023-03-19T23:43:54+01:00
CVE-2022-41794,openimageio: Link to fixing commit

- - - - -
6dece549 by Markus Koschany at 2023-03-19T23:43:56+01:00
CVE-2022-41837,openimageio: Link to fixing commit

- - - - -
88c8703d by Markus Koschany at 2023-03-19T23:43:57+01:00
CVE-2022-41838,CVE-2022-41999,openimageio: Link to fixing commits

- - - - -
83ae7f51 by Markus Koschany at 2023-03-19T23:43:58+01:00
CVE-2022-38143,openimageio: Buster is not affected

The vulnerable code was introduced later

- - - - -
2e12246c by Markus Koschany at 2023-03-19T23:43:59+01:00
CVE-2022-43592,openimageio: Link to pull request

- - - - -
22e314ce by Markus Koschany at 2023-03-19T23:44:01+01:00
CVE-2022-43594,openimageio: Link to pull request

- - - - -
d1bd600f by Markus Koschany at 2023-03-19T23:44:02+01:00
CVE-2022-43595,openimageio: Link to pull request

- - - - -
2b466f30 by Markus Koschany at 2023-03-19T23:44:03+01:00
CVE-2022-43596,CVE-2022-43597,CVE-2022-43598,CVE-2022-43599,CVE-2022-43600

CVE-2022-43601,CVE-2022-43602,openimageio: Link to pull request

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -35990,33 +35990,42 @@ CVE-2022-43602 (Multiple code execution vulnerabilities exist in the IFFOutput::
 CVE-2022-43601 (Multiple code execution vulnerabilities exist in the IFFOutput::close( ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1656
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3676
 CVE-2022-43600 (Multiple code execution vulnerabilities exist in the IFFOutput::close( ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1656
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3676
 CVE-2022-43599 (Multiple code execution vulnerabilities exist in the IFFOutput::close( ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1656
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3676
 CVE-2022-43598 (Multiple memory corruption vulnerabilities exist in the IFFOutput alig ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1655
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3676
 CVE-2022-43597 (Multiple memory corruption vulnerabilities exist in the IFFOutput alig ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1655
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3676
 CVE-2022-43596 (An information disclosure vulnerability exists in the IFFOutput channe ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1654
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3676
 CVE-2022-43595 (Multiple denial of service vulnerabilities exist in the image output c ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1653
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3673
 CVE-2022-43594 (Multiple denial of service vulnerabilities exist in the image output c ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1653
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3673
 CVE-2022-43593 (A denial of service vulnerability exists in the DPXOutput::close() fun ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1652
 CVE-2022-43592 (An information disclosure vulnerability exists in the DPXOutput::close ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1651
+	NOTE: https://github.com/OpenImageIO/oiio/pull/3672
 CVE-2022-43591 (A buffer overflow vulnerability exists in the QML QtScript Reflect API ...)
 	- qt6-declarative 6.4.2+dfsg~rc1-2 (unimportant)
 	- qtdeclarative-opensource-src <unfixed> (unimportant)
@@ -39205,6 +39214,7 @@ CVE-2022-41999 (A denial of service vulnerability exists in the DDS native tile
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027808)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1635
 	NOTE: https://github.com/OpenImageIO/oiio/pull/3625
+	NOTE: https://github.com/OpenImageIO/oiio/commit/e44400feac32d455b49e9c8baffa52ed855ba59b
 CVE-2022-41991 (A heap-based buffer overflow vulnerability exists in the m2m DELETE_FI ...)
 	NOT-FOR-US: Siretta
 CVE-2022-41988 (An information disclosure vulnerability exists in the OpenImageIO::dec ...)
@@ -39215,9 +39225,11 @@ CVE-2022-41988 (An information disclosure vulnerability exists in the OpenImageI
 CVE-2022-41838 (A code execution vulnerability exists in the DDS scanline parsing func ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1634
+	NOTE: https://github.com/OpenImageIO/oiio/commit/e44400feac32d455b49e9c8baffa52ed855ba59b
 CVE-2022-41837 (An out-of-bounds write vulnerability exists in the OpenImageIO::add_ex ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1636
+	NOTE: https://github.com/OpenImageIO/oiio/commit/884dfd6b7c1fd6130390853b5074ddeb48f2f19b
 CVE-2022-41632
 	RESERVED
 CVE-2022-41630
@@ -40500,18 +40512,22 @@ CVE-2022-41977 (An out of bounds read vulnerability exists in the way OpenImageI
 CVE-2022-41794 (A heap based buffer overflow vulnerability exists in the PSD thumbnail ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1626
+	NOTE: https://github.com/OpenImageIO/oiio/commit/884dfd6b7c1fd6130390853b5074ddeb48f2f19b
 CVE-2022-41684 (A heap out of bounds read vulnerability exists in the OpenImageIO mast ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1632
+	NOTE: https://github.com/OpenImageIO/oiio/commit/884dfd6b7c1fd6130390853b5074ddeb48f2f19b
 CVE-2022-41649 (A heap out of bounds read vulnerability exists in the handling of IPTC ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1631
+	NOTE: https://github.com/OpenImageIO/oiio/commit/884dfd6b7c1fd6130390853b5074ddeb48f2f19b
 CVE-2022-41639 (A heap based buffer overflow vulnerability exists in tile decoding cod ...)
 	- openimageio 2.3.21.0+dfsg-1 (bug #1027143)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1633
 	NOTE: https://github.com/OpenImageIO/oiio/pull/3632
 CVE-2022-38143 (A heap out-of-bounds write vulnerability exists in the way OpenImageIO ...)
 	- openimageio 2.4.7.1+dfsg-2 (bug #1027143)
+	[buster] - openimageio <not-affected> (The vulnerable code was introduced later)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2022-1630
 	NOTE: https://github.com/OpenImageIO/oiio/pull/3620
 CVE-2022-36354 (A heap out-of-bounds read vulnerability exists in the RLA format parse ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0662ffd7d93f4164e16e3ea6c36b2b85846df96b...2b466f3073e8b70631ea920314f78aeb0fe86ed5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0662ffd7d93f4164e16e3ea6c36b2b85846df96b...2b466f3073e8b70631ea920314f78aeb0fe86ed5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230319/f1c0cb0a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list